Vicidial is a narrowly scoped open-source call-center platform whose vulnerability footprint centers on its core product and call-center suite, both web-facing systems handling customer interaction and administrative workflows. The recurring exposure pattern reflects application-layer input handling across web interfaces: SQL injection and cross-site scripting vulnerabilities recur as the durable signal, consistent with the demands of a database-backed web application, while public exploit code frequently becomes available for disclosed flaws. Defenders should treat Vicidial instances as internet-reachable administrative systems and prioritize patching for injection-class vulnerabilities; live severity and exploitation figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Vicidial over time
Signals from CVEs in this vendor scope (10 CVEs).
10 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2013-4467MEDIUM Multiple SQL injection vulnerabilities in the agent interface (agc/) in VICIDIAL dialer (aka Asterisk GUI client) 2.8-403a, 2.7, 2.7RC1, and earlier allow (1) remote attackers to e | Mar 11, 2014 | 6.5 | 59 | NO | YES |
CVE-2013-4468MEDIUM VICIDIAL dialer (aka Asterisk GUI client) 2.8-403a, 2.7, 2.7RC1, and earlier allows remote authenticated users to execute arbitrary commands via shell metacharacters in the extensi | May 14, 2014 | 6.5 | 51 | NO | YES |
CVE-2022-34878HIGH SQL Injection vulnerability in User Stats interface (/vicidial/user_stats.php) of VICIdial via the file_download parameter allows attacker to spoof identity, tamper with existing d | Jul 5, 2022 | 8.8 | 40 | NO | YES |
CVE-2022-34877HIGH SQL Injection vulnerability in AST Agent Time Sheet interface ((/vicidial/AST_agent_time_sheet.php) of VICIdial via the agent parameter allows attacker to spoof identity, tamper wi | Jul 5, 2022 | 8.8 | 40 | NO | YES |
CVE-2022-34876HIGH SQL Injection vulnerability in admin interface (/vicidial/admin.php) of VICIdial via modify_email_accounts, access_recordings, and agentcall_email parameters allows attacker to spo | Jul 5, 2022 | 8.8 | 40 | NO | YES |
CVE-2013-7382MEDIUM VICIDIAL dialer (aka Asterisk GUI client) 2.8-403a, 2.7, 2.7RC1, and earlier has a hardcoded password of donotedit for the (1) VDAD and (2) VDCL users, which makes it easier for re | May 17, 2014 | 5.0 | 28 | NO | YES |
CVE-2009-2234HIGH Multiple SQL injection vulnerabilities in admin.php in VICIDIAL Call Center Suite 2.0.5-173 allow remote attackers to execute arbitrary SQL commands via the (1) Username parameter | Jun 27, 2009 | 7.5 | 28 | NO | YES |
CVE-2021-35377MEDIUM Cross Site Scripting vulnerability found in VICIdial v2.14-610c and v.2.10-415c allows attackers execute arbitrary code via the /agc/vicidial.php, agc/vicidial-greay.php, and /vici | Mar 6, 2023 | 6.1 | 22 | NO | NO |
CVE-2022-34879MEDIUM Reflected Cross Site Scripting (XSS) vulnerabilities in AST Agent Time Sheet interface (/vicidial/AST_agent_time_sheet.php) of VICIdial via agent, and search_archived_data paramete | Jul 5, 2022 | 6.1 | 22 | NO | NO |
CVE-2021-46557MEDIUM Vicidial 2.14-783a was discovered to contain a cross-site scripting (XSS) vulnerability via the input tabs. | Feb 15, 2022 | 5.4 | 20 | NO | NO |
Signals from CVEs in this vendor scope (10 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Vicidial.
Media articles that mention a CVE ID that affects a product developed by Vicidial — matched by CVE ID, not by vendor name.